The most recent content from our members.
How would I go about using a Rule in LEM to audit all account actions (creation, modification, enabling, disabling, removal)? I have a rule set up to use certain logs (e.g. UserModifyAttribute.ProviderSID = Microsoft-Windows-Security-Auditing 4720), but when I test it by creating a new user in AD, nothing appears. I tried…
It looks like you're new here. Sign in or register to get started.